Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
-
Updated
Sep 10, 2026 - Python
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Open-source AI-powered offensive security harness for automated penetration testing.
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
Autonomous AI-powered security scanning platform — CLI scanner, web dashboard, and one-command Docker deployment
Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.
Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities.
Shannon-Uncontained. A Docker-free, black‑box‑first fork that treats AI as a fallible witness rather than an oracle: treats uncertainty as a first class citizen via EQBSL epistemic bookkeeping, and agentic recon/analysis/synthesis tuned for “paste url -> pwn box -> ???? -> profit”
open-source pentest management built to be operated by an AI agent
The autonomous pentester that proves its findings — AI-driven, evidence-first, behind-login.
The security engine of your Agentic Company
Mergen is an MCP server that gives your AI a real red team brain. It doesn't just run tools, it picks the right ones, chains them together, and actually makes sense of the output. Built by pentesters, for pentesters who are tired of babysitting scripts.
Semantic Stealth Attacks & Symbolic Prompt Red Teaming on GPT and other LLMs.
RAG Poisoning Lab — Educational AI Security Exercise
Zentra is an open source CLI agent harness tool designed to assist with SAST and DAST on your application
A local proxy that keeps client data out of Claude Code.
A terminal interface to swarm of AI agents to assist during a penetration testing engagement given a RoE.md(Rules of Engagement)
AI-Pentesting-Tool is an educational workflow for using an AI agent with Kali tooling through MCP (Model Context Protocol) in VS Code insiders for white-box and black-box pentesting..
To associate your repository with the ai-penetration-testing topic, visit your repo's landing page and select "manage topics."